Daily Security Intel

Archives
Log in
Subscribe
September 7, 2026

[SecurityIntel] 07 Sep | Active Unauthenticated SSH Hijacking of MikroTik Routers

SECURITYINTEL DAILY BRIEF

■ ThreatIntel Brief

Monday, September 07, 2026

INTEL CONFIDENCE  70%

THREAT LEVEL

CRITICAL

THREAT OF THE DAY

Active Unauthenticated SSH Hijacking of MikroTik Routers

CRITICAL

5

C2 IPs

0

OTX IOCs

5

ARTICLES

■ ANALYST TLDR

Active exploitation of a critical unauthenticated SSH bypass vulnerability in MikroTik RouterOS is allowing attackers to hijack internet-exposed routers and establish administrative persistence. Concurrently, threat actors are leveraging invisible Unicode characters for ASCII smuggling to evade email security filters, while new REVSTEALER-linked modules are actively disabling Windows Defender and Windows Update to deploy cryptocurrency miners.

■ CRITICAL STORIES

CRITICAL#1

Critical MikroTik Vulnerability Exploited in the Wild

Attackers are bypassing authentication on internet-exposed MikroTik SSH services to gain full administrative control and create persistent rogue accounts, requiring immediate patching and compromise assessment.

HIGH#2

Four REVSTEALER-Linked Modules Disable Windows Update and Defender

Newly documented post-compromise modules associated with the REVSTEALER information stealer persist on infected systems to disable critical security controls and run cryptocurrency miners.

HIGH#3

Attackers Conceal Phishing Lures Using Invisible Unicode Characters

Threat actors are utilizing ASCII smuggling techniques with invisible Unicode characters to bypass email security gateways and deliver malicious payloads undetected.

■ CVEs IDENTIFIED

[CVE-TBD]

MikroTik RouterOS — Unauthenticated SSH authentication bypass leading to full administrative takeover

Critical

■ THREAT ACTORS

REVSTEALER Operators

Cybercrime / Financial

Deploying persistent modules to disable Windows Defender/Update and run crypto miners

Unknown Threat Actors

Cybercrime

Exploiting unauthenticated SSH vulnerability in MikroTik routers to add rogue administrative accounts

Phishing Actors

Cybercrime

Utilizing invisible Unicode characters (ASCII smuggling) to evade email security filters

■ ATT&CK TTPs

T1190
Exploit Public-Facing Application | Attackers exploiting internet-exposed MikroTik SSH services.
T1556
Modify Authentication Process | Attackers bypassing SSH authentication on MikroTik routers.
T1136.001
Create Account: Local Account | Attackers adding new administrative accounts to hijacked MikroTik routers.
T1027.007
Obfuscated Files or Information: Stripped Payloads / ASCII Smuggling | Threat actors using invisible Unicode characters to evade email security filters.
T1562.001
Impair Defenses: Disable or Modify Tools | REVSTEALER modules disabling Windows Defender.
T1562.004
Impair Defenses: Disable or Modify System Firewall / Updates | REVSTEALER modules disabling Windows Update.

■ PATCH PRIORITY

[P1 PATCH NOW]≤24h

MikroTik RouterOS — Unauthenticated SSH authentication bypass allowing full administrative control and active exploitation — SANS / CERT Polska

[P2 PATCH NOW]≤72h

Microsoft Windows — REVSTEALER modules disabling Windows Defender and Windows Update to run crypto miners — Elastic Security Labs

■ RECOMMENDED ACTIONS TODAY

1[P1] Immediately apply the latest MikroTik RouterOS patch to resolve the unauthenticated SSH bypass vulnerability ([CVE-TBD]).
2[P1] Audit all MikroTik RouterOS user accounts for unauthorized administrative accounts and restrict SSH access to trusted source IPs only.
3[P2] Update Windows Defender signatures and monitor for unauthorized registry modifications or services attempting to disable Windows Defender or Windows Update (associated with REVSTEALER).
4[P2] Update email security gateway rules to detect and block emails containing invisible Unicode characters used for ASCII smuggling.
LIVE IOC FEED

C2 IP BLOCKLIST  ·  AbuseCH Feodo  ·  Showing 5 of 5

IP ADDRESS

162.243.103.246

PORT

8080

STATUS

OFFLINE

MALWARE

Emotet

COUNTRY

US

IP ADDRESS

50.16.16.211

PORT

443

STATUS

ONLINE

MALWARE

QakBot

COUNTRY

US

IP ADDRESS

34.204.119.63

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

US

IP ADDRESS

178.62.3.223

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

GB

IP ADDRESS

27.133.154.218

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

JP

FULL IOC EXPORT — GOOGLE SHEET

All live IOCs with full SHA256 hashes (OTX), IPs, and domains. 2 tabs: C2 IPs · OTX IOCs
Updated daily · Export as CSV to import directly into your tools

■  Open Full IOC Sheet  →

IOC SOURCES: AbuseCH Feodo  ·  AlienVault OTX
NEWS: THN · KRB · SANS · REC · BC · SW · AWS · GCP · MSFT · U42 · SCH · MWB

Don't miss what's next. Subscribe to Daily Security Intel:
← Newer [SecurityIntel] 08 Sep | Active Zero-Day Exploitation of N-able and Adobe Older → [SecurityIntel] 06 Sep | Active Zero-Day Exploits Target Adobe Commerce and Magento
Powered by Buttondown, the easiest way to start and grow your newsletter.